github / github/roadmap

Dependabot will stop inferring .npmrc [GA]

Ouverte
#1,257 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
Enterprise Free GHES 3.23 GitHub Advanced Security (GHAS) Shipped Team
Langage dominant
Aucune donnée de langage
Étoiles
8.9k
Forks
1.8k
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

### Value Prop
Dependabot's automatic `.npmrc` inference for npm private registries has been a persistent source of broken update runs — failing silently due to incorrect lockfile URLs, format changes, or package manager differences. With this release, customers gain explicit control over registry scopes via a new `scope` property in `dependabot.yml`, and Dependabot generates the correct `.npmrc` automatically. This means fewer mysterious failures, less time debugging registry configuration, and more reliable dependency updates out of the box.

### Expected Outcome
We want to eliminate the most common class of npm private registry failures by replacing an unreliable inference mechanism with an explicit, user-defined configuration model. Customers should experience predictable and correct `.npmrc` generation every time, reducing support burden and increasing confidence in Dependabot for enterprise npm workflows. Success looks like a measurable drop in registry-related Dependabot failures and fewer customer-reported issues around private npm registry setups.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.